# Cyber Company Profiles: Manifest

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-07-15
Canonical: https://cybercompanyprofiles.com/companies/manifest
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Manifest, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [manifestcyber.com](https://www.manifestcyber.com)
- Profile: https://cybercompanyprofiles.com/companies/manifest
- Type: Security for AI, Application Security, Developer Tools
- Also known as: Manifest Cyber
- Market readiness: Established (27/40)
- Defensibility: Contested (14/21)
- Founded: 2022
- Funding: $23M total
- Last updated: 2026-07-15

## Executive Summary

Manifest sells a software and AI supply chain security platform that generates and manages bills of materials for software, AI models, and datasets and monitors them for vulnerability risk. The named, checkable customers are federal, while broader enterprise use stays vendor-claimed. Manifest announced Department of Homeland Security and Air Force contracts in 2023, and it reached FedRAMP High authorization in January 2025 through Palantir's FedStart program. Manifest says no other SBOM management platform holds that authorization, and it is the load-bearing attestation for workloads that require FedRAMP High. The founders are CISA, Defense Digital Service, and Palantir alumni. The bill-of-materials generation itself is reproducible by funded scanners.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Manifest is a software and AI supply chain security company whose platform generates and manages SBOMs and AI bills of materials to inventory components, models, and datasets and monitor them for risk. | [\[f1\]](#company-detail-sources) |
| Founded | 2022 | [\[f2\]](#company-detail-sources) |
| HQ | Connecticut, USA | [\[f2\]](#company-detail-sources) |
| Funding | $23M total | [\[f2\]](#company-detail-sources) |
| Latest funding | Series A (April 2025) | [\[f2\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Manifest Platform | Generates and manages SBOMs across the application fleet in SPDX, CycloneDX, and VEX formats, then continuously monitors components for vulnerabilities, license, and supplier risk. |
| Manifest AI Risk | AI bill-of-materials line that discovers and inventories AI models and datasets across the enterprise, tracks their provenance, and monitors them for vulnerabilities and license risk. |

## Matrix Coverage

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f3\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| AI Model |  | ✓ |  | ✓ |  |  |
| Training Data |  | ✓ |  |  |  |  |

Manifest AI Risk discovers and inventories AI models and dependencies with provenance, including shadow AI, continuously monitors them for vulnerabilities, and extends the bill of materials to datasets. These capabilities are mapped to the AI Defense Matrix.

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f4\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Applications | ✓ |  | ✓ |  |  |

The Manifest Platform generates and manages software bills of materials for applications across the fleet and continuously monitors their open-source and third-party components for vulnerabilities and license risk. These capabilities are mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (27/40)**

Analyzed 2026-06-26. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 4/5 | Manifest names a precise problem, that organizations deploy software and AI without an inventory of what is inside, and ties it to concrete drivers including federal SBOM mandates and the Log4Shell event. Axios independently corroborates the federal SBOM pressure, so the pain is documented beyond vendor marketing. \[[s1](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | The platform spans SBOM generation in SPDX, CycloneDX, and VEX formats, continuous monitoring, and an AIBOM line for models and datasets, with public API and user documentation. Public technical depth is adequate but thinner than detailed architecture evidence, and the AI Risk page renders as a marketing summary rather than a documented capability surface. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| Market Timing | 4/5 | Federal SBOM mandates that followed Log4Shell and EO 14028 in the past few years made software bills of materials a buying requirement rather than a nice-to-have, and the 2022-founded company built directly into that demand, with the AIBOM line extending it to enterprise AI adoption. Multiple regulatory drivers within the window support a strong read. A closing risk is incumbent scanners folding in SBOM generation. \[[s1](#profile-analysis-sources), [s6](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | Daniel Bardenstein was CISA Chief of Tech Strategy and ran Defense Digital Service programs, and Axios describes the team as former Pentagon and Palantir employees, which is government and platform pedigree without a prior security-startup exit or sustained publication record. \[[s8](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | The named, checkable traction is federal, covering DHS and Air Force contracts and a Palantir FedStart partnership behind the FedRAMP authorization. Manifest also tells SecurityWeek it serves Fortune 500 and regulated-industry enterprises, but no commercial reference customer is named, so government deals plus reputable venture backing support a solid 3. \[[s6](#profile-analysis-sources), [s7](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | Manifest has raised $23 million total, including a $15 million Series A led by Ensemble VC, a raise sized to a focused federal and AIBOM motion. Output is visible in the FedRAMP High authorization and the shipped AI Risk line, and private margins cap confirmation of efficiency at this level. \[[s5](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | SBOM management is a clearly emerging category buyers place without vendor coaching, driven by federal mandates, and the AIBOM extension fits the same stack slot. Independent reporting in Axios treats SBOM as an established federal procurement category, and the absence of an analyst placement keeps it a step below the strongest peer. \[[s1](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | SBOM and AIBOM generation is a plausible addition for software composition analysis and AppSec platforms and code-hosting vendors already adjacent to the buyer. The FedRAMP High authorization and federal install base are the structural edge, but the core capability is reproducible, matching the supply-chain security peers. \[[s2](#profile-analysis-sources), [s9](#profile-analysis-sources)\] |

### Business Risks

- A larger software composition analysis or AppSec platform such as Snyk, Sonatype, or JFrog could fold SBOM and AIBOM generation into an existing product, eroding Manifest's standalone case for commercial buyers.
- Manifest's named, checkable traction concentrates in federal and defense agencies, so a slowdown in government SBOM mandates or budgets would remove its strongest demand signal before named commercial proof is established.
- The FedRAMP High edge depends on the Palantir FedStart hosting relationship, and a change in that partnership or a competitor obtaining its own federal authorization would narrow the differentiator.
- The public record shows no named commercial enterprise reference customer, so if the company cannot convert its federal credibility into commercial logos, growth stays tied to a single buyer segment.

### Problem & Market

Manifest sells to the security and product teams that must answer what is inside the software and AI their organization builds and buys. The buyer is the application-security, product-security, or supply-chain owner who faces vulnerability and license risk hidden in third-party components and, increasingly, in AI models and datasets.

Federal mandates anchor the demand. Manifest traces its origin to the December 2021 Log4Shell event, and Axios documents the Biden administration pushing agencies and critical-infrastructure operators toward software bills of materials. That regulatory pressure makes the problem concrete and time-bound rather than a vendor-argued need.

The AIBOM extension widens the same problem to AI supply chains. Manifest frames models, datasets, licenses, and dependencies as assets the security owner must inventory and monitor, which keeps the new line inside the existing buyer relationship rather than opening a separate market. \[[s1](#profile-analysis-sources), [s6](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Product Capabilities

The Manifest Platform centers on generating and managing software bills of materials across an organization's application fleet. It supports SPDX, CycloneDX, and VEX formats, analyzes binaries and deployed software beyond source repositories, and monitors components continuously for vulnerability and license risk. The platform organizes this into Product Security, Supplier Risk, and AI Risk lines.

The AI Risk line is the bill-of-materials idea applied to AI. It discovers and inventories AI models and datasets with provenance, including shadow AI, and monitors them for vulnerabilities. The AI Defense Matrix Catalog records this discovery and monitoring of models, with dataset provenance as a secondary capability.

Public technical depth is adequate rather than deep. Manifest publishes API and user documentation, but the AI Risk page reads as a marketing summary, and the reviewed sources do not expose architecture detail or third-party evaluations that would corroborate the capability claims independently. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources)\]

### Competitive Positioning

Manifest competes in software supply chain security against SBOM and software composition analysis vendors. Sonatype, Lineaje, and Cycode overlap its component-inventory and vulnerability-monitoring scope, and larger scanning platforms could add SBOM generation as a feature, which keeps the standalone case under pressure for commercial buyers.

The differentiator is federal. Manifest reached FedRAMP High authorization in January 2025 through Palantir's FedStart program and says no other SBOM management platform holds that authorization. Combined with named DHS and Air Force work and a founding team of CISA, Defense Digital Service, and Palantir alumni, that gives Manifest a public-sector position the commercial-focused peers do not hold.

The risk is the mirror image of the strength. The named, checkable buyers are federal, and although Manifest tells SecurityWeek it serves Fortune 500 and regulated-industry enterprises, the reviewed sources name no commercial reference customer. Converting federal credibility into named commercial logos is the test the public record does not yet answer. \[[s9](#profile-analysis-sources), [s7](#profile-analysis-sources), [s10](#profile-analysis-sources)\]

### Go-to-Market & Traction

Manifest's go-to-market motion runs through the federal channel. The company books work directly with agencies and partners with Palantir, whose FedStart program carried Manifest to FedRAMP High and provides the authorized hosting environment for government delivery.

The named traction is government. Axios reported contracts with the Department of Homeland Security and the Air Force alongside the $6 million seed, and the FedRAMP announcement cites prior work at the Department of Defense and DHS. These are real, named buyers in a demanding segment.

Commercial proof is less specific. Manifest tells SecurityWeek its platform serves Fortune 500 and regulated-industry enterprises, but the reviewed sources name no commercial reference customer and disclose no public pricing. The checkable buyers stay federal while the commercial use is vendor-asserted. \[[s6](#profile-analysis-sources), [s7](#profile-analysis-sources), [s10](#profile-analysis-sources)\]

### Team & Credibility

Manifest was founded in 2022 by a team the company and the press describe as DOD, CISA, and Palantir alumni. Daniel Bardenstein, the CEO and co-founder, was Chief of Tech Strategy at CISA and led cybersecurity programs at the Defense Digital Service, including work on the Cybersecurity Performance Goals.

The founding pedigree is public-sector and platform depth. Before government, Bardenstein directed product teams at Exabeam and Palantir, and Axios describes the founders as former Pentagon and Palantir employees. That background maps directly onto the federal SBOM buyer Manifest serves.

The credibility is government-domain rather than startup-exit. The team shows deep agency relationships and supply-chain policy fluency, but the reviewed sources do not show prior security-company exits, so the signal is strong domain standing rather than a serial-founder track record. \[[s8](#profile-analysis-sources), [s6](#profile-analysis-sources)\]

### Trust Readiness

Manifest's security page displays FedRAMP High, SOC 2, ISO 27001, and GDPR seals. The SOC 2, ISO 27001, and GDPR badges render as images, with no inspectable report or third-party trust portal behind them in the reviewed sources. Manifest says no other SBOM management platform holds FedRAMP High Authorization.

FedRAMP High is the differentiating attestation. Manifest reached it in January 2025 through Palantir's FedStart program, which the company presents as authorizing it to handle sensitive government data. The authorization is a barrier a commercial-only rival has not cleared.

The displayed SOC 2 and ISO 27001 seals are the commercial floor. They are table-stakes a buyer expects from a vendor that reads software components, and they ease procurement without creating a barrier a funded rival could not also clear. \[[s9](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Sonatype | competes with | Software supply chain and software composition analysis platform with SBOM management, overlapping Manifest's component-inventory and vulnerability-monitoring scope. |
| Lineaje | competes with | Software supply chain security vendor with SBOM and AIBOM management, directly overlapping Manifest's bill-of-materials positioning. |
| Cycode | competes with | Application security platform whose software supply chain security and SCA coverage overlaps Manifest's component-risk scope. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (14/21)**

Band guidance: reinforce or reposition. Analyzed 2026-07-15. Scope: whole company.

Manifest competes in software supply chain security on terms close to its SBOM and software composition analysis rivals, and the bill-of-materials engine is reproducible by a funded scanner. The federal position is what sets the record apart. Manifest reached FedRAMP High authorization in January 2025 through Palantir's FedStart program. It pairs that with named DHS and Air Force work and CISA and Defense Digital Service founders. The SOC 2 and ISO 27001 seals it displays are a procurement floor any rival can clear, and no cross-customer data asset appears in the record. Manifest is most defensible inside government, where the authorization and agency ties raise switching cost. It is weakest in the commercial market it targets but shows no reference customer.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Manifest delivers software the customer connects to its own estate and runs. Bill-of-materials generation, monitoring, and AI inventory are automated output, not a human-expertise service that accepts accountability. \[[s2](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Wiring Manifest into a customer's software estate and an accumulating SBOM and AIBOM history builds context a team must reabsorb to leave, and the FedRAMP-authorized federal deployment deepens that further. The cost is real in re-integration effort, short of a network effect or mandated data residency. \[[s2](#deep-dive-sources), [s7](#deep-dive-sources)\] |
| Compliance Moat | 2/3 | Manifest holds FedRAMP High Authorization, reached in January 2025 through Palantir's FedStart program, an inspectable federal authorization that creates procurement friction for rivals in deals that require FedRAMP High, a step beyond the SOC 2 and ISO 27001 seals it also displays. \[[s7](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Generating accurate bills of materials across binaries, embedded code, and real deployments, then extending provenance tracking to AI models and datasets, is genuinely hard engineering. \[[s1](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | Manifest's named buyers are federal and defense agencies including DHS, the Air Force, and the Department of Defense, a demanding, high-assurance segment. That evidenced buyer rests on government rather than Fortune 500 references. \[[s6](#deep-dive-sources), [s7](#deep-dive-sources)\] |
| Layer | 2/3 | Manifest sits in the software build and supply-chain visibility path, an important position, but removing it costs the buyer inventory coverage and compliance evidence rather than breaking production software. \[[s2](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The reviewed sources show per-customer SBOM and AIBOM data generated from each buyer's own estate, but disclose no unique cross-customer corpus or named non-public dataset behind the product, so the data moat appears limited. \[[s2](#deep-dive-sources), [s4](#deep-dive-sources)\] |

### Strategic Market Segmentation

Manifest sells to the security and product teams accountable for the software and AI an organization builds and buys. The federal and defense market is the evidenced core, where Axios reported DHS and Air Force contracts and the FedRAMP announcement cites prior Department of Defense work.

The buyer is the supply-chain, product-security, or compliance owner who faces government pressure to inventory software components. Manifest's origin in the December 2021 Log4Shell event and the federal SBOM push that followed place it at the regulated, high-assurance end of the market.

The AIBOM line extends the same buyer to AI. Manifest frames models, datasets, and their provenance as assets the security owner must inventory and monitor, which keeps the new motion inside the existing federal and enterprise relationship rather than opening a separate market. \[[s6](#deep-dive-sources), [s7](#deep-dive-sources), [s3](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

Manifest's core capability is generating and managing software bills of materials across an organization's fleet. It supports SPDX, CycloneDX, and VEX formats and analyzes binaries, embedded code, and real-world deployments beyond source repositories, then monitors components for vulnerability and license risk.

The AI Risk line applies the bill-of-materials idea to AI. The product pages describe automated AI supply chain risk assessments across models, datasets, licenses, and dependencies, and the catalog entry captured in June recorded discovery and inventory of models and datasets with provenance, including shadow AI.

The depth is real but lightly documented in public. Manifest publishes API and user documentation, yet the reviewed product pages read as marketing summaries, and no third-party technical evaluation appears in the sources to corroborate the capability claims independently. \[[s1](#deep-dive-sources), [s4](#deep-dive-sources), [s3](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Federal is Manifest's strongest publicly evidenced go-to-market motion, while the overall sales mix stays undisclosed. The company books work with agencies directly and partners with Palantir, whose FedStart program carried it to FedRAMP High and provides the authorized hosting environment used for government delivery.

The named traction is government. Axios reported DHS and Air Force contracts alongside the $6 million seed, and the FedRAMP announcement names prior Department of Defense and DHS work. These are real buyers in a demanding, slow-procurement segment.

Commercial proof is less specific. Manifest tells SecurityWeek its platform is already used by Fortune 500 companies and enterprises in automotive, defense, and financial services, but the reviewed sources name no commercial reference customer and publish no pricing. The named, checkable buyers stay federal while the commercial use is vendor-asserted. \[[s6](#deep-dive-sources), [s7](#deep-dive-sources), [s11](#deep-dive-sources)\]

### Pricing Model

Manifest does not publish prices on the reviewed pages, which is standard for a security platform sold into federal and enterprise accounts through evaluation and a quote. Buyers reach a number through a demo rather than a public price list.

The packaging signal is the three-line platform. Product Security, Supplier Risk, and AI Risk suggest a modular platform contract rather than a single-metric seat or scan charge, though the reviewed sources do not disclose the billing unit.

The absence of public pricing is a disclosure gap rather than a finding about the model. Hidden pricing is consistent with the negotiated federal and enterprise deals the rest of the evidence describes. \[[s10](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Product Delivery & Operations

Manifest delivers SaaS that generates, imports, analyzes, and monitors bills of materials, including across binaries, embedded code, and real-world deployments. The catalog records a SaaS deployment, and the platform runs against the customer's own software and AI estate.

The FedRAMP High path runs through Palantir's FedStart, which provides the authorized hosting environment for government customers. That dependency is both the enabler of the federal motion and a third-party relationship the delivery model rests on.

The operational burden sits with the customer's security and product teams, who act on the generated inventory and the vulnerability and license findings. Public materials present Manifest as customer-operated platform software rather than a managed service that accepts accountability for outcomes. \[[s7](#deep-dive-sources), [s2](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Earning Customers' Trust

Manifest's security page displays FedRAMP High, SOC 2, ISO 27001, and GDPR seals. The SOC 2, ISO 27001, and GDPR badges render as images on that page, and no inspectable report or third-party trust portal backs them in the reviewed sources.

FedRAMP High is the load-bearing attestation. Manifest reached it on January 7, 2025 through Palantir's FedStart program, which the company presents as authorizing it to handle sensitive government data. The authorization is procurement leverage in deals that require FedRAMP High.

The displayed SOC 2 and ISO 27001 seals are the commercial floor. They are table-stakes for a vendor that reads software components, easing procurement without creating a barrier a funded rival could not also clear. \[[s9](#deep-dive-sources), [s7](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Manifest positions a single platform across the software and AI supply chain, from source code to vendor software to model. The three lines, Product Security, Supplier Risk, and AI Risk, share the bill-of-materials engine as the common spine.

The Palantir relationship is the defining ecosystem tie. FedStart provides the FedRAMP-authorized environment, which is the integration that opens the federal market and distinguishes Manifest from commercial-only supply-chain vendors.

The ecosystem boundary cuts both ways. The same SBOM and SCA scope sits in the established software-composition-analysis category, so the standalone platform competes against features existing vendors can add for their installed buyers. \[[s2](#deep-dive-sources), [s7](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Team & Execution Capability

Manifest was founded in 2022 by a team the company and press describe as DOD, CISA, and Palantir alumni. Daniel Bardenstein, CEO and co-founder, was Chief of Tech Strategy at CISA and led Defense Digital Service cybersecurity programs across the Department of Defense.

The founding background is public-sector depth plus platform engineering. Bardenstein previously directed product teams at Exabeam and Palantir, and Axios describes the founders as former Pentagon and Palantir employees, which maps onto the federal SBOM buyer Manifest serves.

The credibility is domain standing rather than a founder-exit record. The team shows deep agency relationships and supply-chain policy fluency, and while the about page notes co-founder Marc Frankel's leadership roles at Expanse, acquired by Palo Alto Networks, the reviewed sources document no prior founder-led exit, so the signal is government trust rather than serial-founder proof. \[[s8](#deep-dive-sources), [s6](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [https://www.manifestcyber.com/](https://www.manifestcyber.com/) | official | 2026-06-25 |
| f2 | [https://www.securityweek.com/manifest-raises-15-million-for-sbom-management-platform/](https://www.securityweek.com/manifest-raises-15-million-for-sbom-management-platform/) | press | 2026-06-25 |
| f3 | [https://catalog.aidefensematrix.com/catalog.json](https://catalog.aidefensematrix.com/catalog.json) | official | 2026-06-25 |
| f4 | [https://www.manifestcyber.com/platform](https://www.manifestcyber.com/platform) | official | 2026-06-25 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Manifest Cyber homepage: SBOM and AI supply chain security](https://www.manifestcyber.com/) “Manifest Cyber uncovers hidden software and AI supply chain risks across your entire product line, from source code to third-party components. Automate compliance, act on real threats, and save weeks of manual work.” | official | 2026-06-25 |
| s2 | [Manifest Platform: Product Security, Supplier Risk, and AI Risk](https://www.manifestcyber.com/platform) “The Manifest Platform addresses key challenges like software supply chain attacks, AI model risk, compliance gaps, and limited visibility by securing the entire software and AI lifecycle, from the code you build to the tools and models you buy.” | official | 2026-06-25 |
| s3 | [Manifest AI Risk: AI supply chain risk assessments](https://www.manifestcyber.com/ai-risk) “Automate AI supply chain risk assessments across models, datasets, licenses, and dependencies.” | official | 2026-06-25 |
| s4 | [AI Defense Matrix Catalog: Manifest AI Risk mapping](https://catalog.aidefensematrix.com/catalog.json) “Discovers and inventories models and dependencies with provenance, including shadow AI, and continuously monitors them for vulnerabilities.” | official | 2026-06-25 |
| s5 | [SecurityWeek: Manifest raises $15M Series A, total raised $23M](https://www.securityweek.com/manifest-raises-15-million-for-sbom-management-platform/) “Manifest has raised $15 million in a Series A funding round led by Ensemble VC ... that brings the total raised by the company to $23 million. Founded in 2022, the Connecticut-based cybersecurity startup.” | press | 2026-06-25 |
| s6 | [Axios: Manifest lands DHS and Air Force contracts, raises $6M seed](https://www.axios.com/2023/05/18/manifest-government-contracts-cyber-software) “Manifest Cyber, a one-year-old startup founded by former Pentagon and Palantir employees, unveiled two contracts on Thursday with the Department of Homeland Security and the Air Force, and closed a $6 million seed round.” | press | 2026-06-25 |
| s7 | [Manifest achieves FedRAMP High Authorization through Palantir FedStart](https://www.prnewswire.com/news-releases/manifest-achieves-fedramp-high-authorization-through-palantir-technologies-302343468.html) “Manifest ... achieved FedRAMP High authorization through Palantir Technologies' FedStart program. Manifest can deliver its industry-leading SBOM and AIBOM management platform to government customers in a FedRAMP-authorized environment.” | press | 2026-06-25 |
| s8 | [About Manifest Cyber: founders and mission](https://www.manifestcyber.com/about) “Daniel Bardenstein, CEO and co-founder, served as the Chief of Tech Strategy at CISA and led cybersecurity programs at the Defense Digital Service. Founded by DOD, CISA, and Palantir alumni.” | official | 2026-06-25 |
| s9 | [Security at Manifest Cyber: FedRAMP High, SOC 2, ISO 27001, GDPR seals](https://www.manifestcyber.com/security) “Manifest is the only SBOM management platform with FedRAMP High Authorization. Manifest empowers federal agencies and defense partners to manage software supply chain risk with confidence.” | official | 2026-06-25 |
| s10 | [SecurityWeek: Manifest claims Air Force, DHS, and Fortune 500 use](https://www.securityweek.com/manifest-raises-15-million-for-sbom-management-platform/) “Manifest says its platform is already used by the US Air Force, DHS, various Fortune 500 companies, and enterprises in the automotive, defense, and financial services sectors.” | press | 2026-06-25 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Manifest Cyber homepage: SBOM and AI supply chain security](https://www.manifestcyber.com/) “Manifest Cyber uncovers hidden software and AI supply chain risks across your entire product line, from source code to third-party components. Manifest supports formats like SPDX, CycloneDX, and VEX, and go beyond repositories to analyze binaries, embedded code, and real-world deployments.” | official | 2026-06-25 |
| s2 | [Manifest Platform: Product Security, Supplier Risk, and AI Risk](https://www.manifestcyber.com/platform) “The Manifest Platform addresses key challenges like software supply chain attacks, AI model risk, compliance gaps, and limited visibility by securing the entire software and AI lifecycle, from the code you build to the tools and models you buy.” | official | 2026-06-25 |
| s3 | [Manifest AI Risk: AI supply chain risk assessments](https://www.manifestcyber.com/ai-risk) “Automate AI supply chain risk assessments across models, datasets, licenses, and dependencies.” | official | 2026-06-25 |
| s4 | [AI Defense Matrix Catalog: Manifest AI Risk mapping](https://catalog.aidefensematrix.com/catalog.json) “Discovers and inventories models and dependencies with provenance, including shadow AI, and continuously monitors them for vulnerabilities. The AIBOM extends coverage to datasets, documenting their provenance alongside models for compliance.” | official | 2026-06-25 |
| s5 | [SecurityWeek: Manifest raises $15M Series A, total raised $23M](https://www.securityweek.com/manifest-raises-15-million-for-sbom-management-platform/) “Manifest has raised $15 million in a Series A funding round led by Ensemble VC ... that brings the total raised by the company to $23 million. Founded in 2022, the Connecticut-based cybersecurity startup.” | press | 2026-06-25 |
| s6 | [Axios: Manifest lands DHS and Air Force contracts, raises $6M seed](https://www.axios.com/2023/05/18/manifest-government-contracts-cyber-software) “Manifest Cyber, a one-year-old startup founded by former Pentagon and Palantir employees, unveiled two contracts on Thursday with the Department of Homeland Security and the Air Force, and closed a $6 million seed round.” | press | 2026-06-25 |
| s7 | [Manifest achieves FedRAMP High Authorization through Palantir FedStart (vendor release via PRNewswire)](https://www.prnewswire.com/news-releases/manifest-achieves-fedramp-high-authorization-through-palantir-technologies-302343468.html) “WESTPORT, Conn., Jan. 7, 2025. Manifest ... achieved FedRAMP High authorization through Palantir Technologies' FedStart program ... Manifest has a proven history of success with various federal agencies, including at the Department of Defense and the Department of Homeland Security.” | official | 2026-06-25 |
| s8 | [About Manifest Cyber: founders and mission](https://www.manifestcyber.com/about) “Daniel Bardenstein, CEO and co-founder, served as the Chief of Tech Strategy at CISA, and at the Defense Digital Service led cybersecurity programs across the Department of Defense. Before government, Daniel directed product teams at Exabeam and Palantir.” | official | 2026-06-25 |
| s9 | [Security at Manifest Cyber: FedRAMP High, SOC 2, ISO 27001, GDPR seals](https://www.manifestcyber.com/security) “Manifest is proud to protect customer data by upholding industry standards and maintaining rigorous compliance certifications. Manifest is the only SBOM management platform with FedRAMP High Authorization.” | official | 2026-06-25 |
| s10 | [Manifest demo page: platform value points](https://www.manifestcyber.com/get-a-demo) “Gain a live, prioritized view of vulnerable components in your software. Monitor and govern the use of generative AI models and data, enforcing responsible AI practices while reducing risk.” | official | 2026-06-25 |
| s11 | [SecurityWeek: Manifest claims Air Force, DHS, and Fortune 500 use](https://www.securityweek.com/manifest-raises-15-million-for-sbom-management-platform/) “Manifest says its platform is already used by the US Air Force, DHS, various Fortune 500 companies, and enterprises in the automotive, defense, and financial services sectors.” | press | 2026-06-25 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
